MB Bluejuice
Security

Unknown administrator accounts in WordPress

A rogue administrator is not the cause of a breach but its consequence. Here is what it tells you.

· updated 2026-10-07

When you find an account you did not create, the first instinct is to delete it. That is understandable but premature.

What the account tells you

  • The creation date is an approximate breach time. Log analysis starts from there.
  • The email address often recurs across campaigns and helps identify the toolkit used.
  • The last login shows whether access is still active.

Deleting the account destroys all of this, and if the attacker still has another route in, they simply create a new one.

Why one account is never just one account

In the cases we have investigated, a rogue administrator almost always comes with at least one of these:

  • a webshell file allowing return without logging in;
  • a modified wp_options value that recreates the account;
  • a scheduled WordPress task (cron) that recreates it;
  • an added public SSH key on the server.

That is why deleting the account without investigating usually means it is back within a week. More on that in the article about reinfection.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.